A free ROI stress test. Pressure-test your ROI model against the questions a CFO will actually ask, surface weak assumptions before finance does, and get a defensibility score in three minutes.
Most ROI models are not rejected because the math is wrong. They are rejected because the model behind the number cannot be reconstructed by the person reviewing it. A 312% return looks unbeatable on a slide and dissolves the moment a CFO asks where the productivity figure came from, what happens if adoption is half of plan, or whether the headcount savings are already in next year's operating budget. The arithmetic was never the problem — the chain of evidence was.
Defensibility is the discipline of building an ROI model that survives that review. It means every input traces to a source, every benefit ties to an operational metric the buyer already reports on, every assumption has a sensitivity range, and the downside case is on the same page as the base case. It also means being honest about dependencies — the integrations, the change management, the data quality — that quietly determine whether the projected return ever lands.
The ROI Defensibility Checker is a structured way to find the gaps before they cost you the deal. It does not generate an ROI for you and it is not a calculator. It evaluates the model you already have against nine questions finance teams use to challenge vendor ROI — how baselines and improvement rates were sourced, whether scenarios and sensitivity were tested, and what the return depends on — and gives you a verdict with the specific weak assumptions to fix.
Run it before the meeting, not after. The cost of running it is three minutes. The cost of not running it is rework, delay, and a buyer who has lost confidence that the numbers were ever real.
How solid are the assumptions underlying your ROI calculation?
The checker asks nine multiple-choice questions in three groups of three: assumptions, ranges and scenarios, and dependencies. Each answer scores from 0 to 3, so each group is scored out of 9 and the total out of 27. Every question counts equally.
Assumptions asks how baseline costs and volumes are sourced, how improvement rates were determined — measured results from similar implementations score highest, optimistic estimates chosen to make the numbers work score zero — and whether assumptions are documented with owners. Ranges and scenarios asks whether you present conservative, expected and optimistic cases, how precise the output figures are, and whether sensitivity on key variables has been tested and documented. Dependencies asks how much the ROI relies on client execution, whether the implementation timeline is based on real implementations or designed to show faster payback, and whether external dependencies are documented with mitigation plans.
The result is an overall verdict — Low CFO Risk at 22 or above, Medium from 14 to 21, High below 14 — a heatmap rating each group Strong (7–9), At Risk (4–6) or Weak (0–3), a weak-assumption alert for every question where you chose one of the two weakest answers, and a list of the defensibility strengths the model already has.
The right time to run the defensibility check is in the window between drafting the ROI model and presenting it externally — typically two or three days before a finance review or executive readout. By that point the inputs are stable enough to evaluate, but there is still time to fix what the diagnostic surfaces. Running it after the meeting is informative but rarely useful.
The tool is designed for the people who own the model. That includes value engineers and value consultants building deal-specific business cases, account executives writing ROI summaries for procurement, customer success managers preparing renewal or expansion cases, finance business partners scrubbing a vendor proposal before approval, and product marketing teams maintaining the ROI templates the field uses. It is equally useful for buyers — anyone reviewing an inbound vendor business case can use it to identify which sections to challenge.
It is less useful for very early-stage discovery work where a directional ROI is appropriate. The checker assumes you have a model with explicit assumptions; it cannot evaluate a one-line back-of-envelope estimate.
After the nine questions, the checker returns a verdict, a three-part heatmap, weak-assumption alerts and a list of strengths. Here is an example for a model built on client SME estimates, with rates taken from standard assumptions, one scenario, no sensitivity testing and an aggressive timeline.
Weak assumption alerts
The alerts are the most useful part of the output. Each one names the weak assumption and the change that fixes it, which makes it easy to take back to the spreadsheet. The score itself is secondary — the goal is not to maximize the number, it is to fix the items that would have lost the deal.
Treat the alerts as a punch list, not a grade, and start with the critical ones: get client sign-off on current-state baseline data, cite specific comparable implementations for improvement rates, replace a single-point estimate with conservative, expected and optimistic scenarios, and separate the value the product delivers from the value that depends on the client's own transformation. Then work through the warnings — attribute each assumption to an owner and date, round outputs and show ranges, document sensitivity on the variables that move the result, use realistic implementation durations, and write down external dependencies with mitigation plans.
Once the fixes are in, run the checker a second time; a total of 22 or more moves the verdict to Low CFO Risk. For the patterns behind these alerts — false precision, risk blindness, timeline fantasy and missing dependencies among them — read Why ROI Models Collapse Under CFO Review.
The checker looks at the ROI model. The Business Case Readiness Diagnostic looks at the case around it: whether baseline data is attributed to named client stakeholders, how current it is, whether every number has a documented source, and whether someone else could trace outputs back to inputs. If you do not have a model to test yet, the free SaaS ROI calculator and cybersecurity ROI calculator produce a first one from a handful of inputs.
Common questions about ROI defensibility, how the diagnostic works, and how to use the result.
A defensible ROI model is one whose assumptions, data sources, and scenarios survive scrutiny from finance and procurement without rework. It cites where each input came from, ties benefits to operational metrics the buyer already tracks, includes a downside case as well as a base case, and isolates dependencies the deal could pivot on. If a model cannot be reconstructed by the CFO from the inputs alone, it is not defensible.
A standard ROI calculator computes a number. The ROI Defensibility Checker evaluates the model behind the number. Two models can produce the same headline ROI and have very different odds of approval — the difference is in assumption quality, sensitivity coverage, and the chain of evidence behind each input. This tool scores those qualitative attributes, not the arithmetic.
Nine, one per question: baseline data that has not been validated with the client; improvement rates that are standard or optimistic rather than evidenced; assumptions with no documented owner; a single-point estimate with no scenarios; false precision in the outputs; no sensitivity testing; an ROI that depends heavily on client execution; implementation timelines chosen to show faster payback; and external dependencies that have not been mapped. Four of them — unvalidated baselines, unevidenced improvement rates, missing scenarios and heavy execution dependency — are flagged as critical; the rest as warnings.
About three minutes for nine questions. The questions are short, the inputs are multiple-choice, and you do not need to upload your model. The output is generated immediately on the same page — there is no email gate and no waiting period.
Anyone whose ROI model will be reviewed by someone with budget authority: value engineers preparing a deal, AEs writing a business case for procurement, customer success building an expansion case, or finance partners scrubbing a vendor proposal. It is most useful before the model is presented externally — running it after rejection is too late.
The total, out of 27, reflects how many of the standard CFO objections the model already answers. 22 or more is Low CFO Risk: the model can survive a typical finance review with limited rework. 14 to 21 is Medium and below 14 is High. A low score does not mean the ROI is wrong — it means the case behind it is incomplete and a finance reviewer will have unanswered questions, which materially reduces the odds of a clean approval.
No. The checker is diagnostic, not generative. It tells you where your existing model is weak and what to fix. The fixes themselves — better baselines, sensitivity scenarios, cleaner attribution — still require you to gather the underlying inputs.
The most common reasons are not arithmetic errors. They are: assumptions the CFO cannot trace to a source, benefits that are not measurable in the buyer's reporting system, missing downside cases, dependencies that were not disclosed, and projected savings that conflict with the headcount or budget plan already in place. Strong numbers built on opaque inputs lose to weaker numbers backed by clear evidence.
No personal information is collected to use the tool. The diagnostic runs entirely client-side — your answers are not stored on our servers and there is no form to submit before seeing your result.
Other free tools to strengthen your business case before finance reviews it.
Discover the gaps in your business case before the CFO does. Get your readiness score, see exactly where you're vulnerable, and know what to fix.
Stop modeling everything. Find out which value drivers actually matter for your deal—and which ones to leave out of your business case.
Assess whether your value work is ready for platform infrastructure. Four questions to understand where repeatability, consistency, and delivery stand today.